Database/Container, Kubernetes & orchestration

Calico: Application Layer Policy (Dikastes) does not normalise URL paths, so path-traversal and encoded
CVSS 7.9CVE-2026-6540Container, Kubernetes & orchestrationcurated
Impact
Application Layer Policy (Dikastes) does not normalise URL paths, so path-traversal and encoded slashes bypass HTTP rules
Who can reach it
Unauthenticated network reaching a policy-protected service
What to do
Rolling Calico upgrade; do not rely on ALP HTTP rules as the only authorization
References
Related entries
- Calico: DeleteCollection skips AuthorizeTierOperation, so a tenant can delete tiered NetworkPolicies theyCVE-2026-41187 · CalicoMedium
- Calico: install-cni logs the rendered CNI config including the substituted service-account tokenCVE-2026-41184 · CalicoMedium
- Calico: Azure IPAM helper logs the mutated CNI config including credentialsCVE-2026-41185 · CalicoMedium
- Calico: kube-controllers and Goldmane bind an unauthenticated pprof listener to 0.0.0.0CVE-2026-41186 · CalicoMedium
- Calico: Route hijacking via the floating IP featureCVE-2022-28224 · CalicoMedium
- Docker Desktop: Trojan docker-credential-wincred.exe in a world-writable path gives local privilege escalationCVE-2019-15752 · Docker DesktopHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.